Privacy policy (the app)

Last updated [pending: set when C4 review lands] · customised template, see the review banner below

This is a customised template, checked against the app’s own source code at the commit it was written on, then re-read twice more for completeness: once for general gaps (retention, IP handling, EU/UK-style rights), and again from an India-specific lawyer-review checklist (the DPDP Act notice below). It has not yet been skimmed by an actual, licensed lawyer. Looking for the wishlist site’s own, separate privacy notice? See the wishlist privacy page instead. This page is about the installed desktop app.

The short version

Nudge runs locally. Search, math, unit conversion, and system commands never leave your machine. Nudge uses the network only when you use a network feature, plus a small, infrequent licence and update check. The only things that ever go out over the network are the six calls listed below, and every one of them is either something you triggered (a purchase, a bug report you chose to send, a currency conversion you typed) or that licence/update check. Nothing you type is ever sent.

The exact network calls

CallTriggerSentReceived
ActivationYou enter a licence keyYour licence key, a hashed machine fingerprint (below), the app versionAn activation token, the server time, the email tied to your licence
Licence heartbeatAutomatic, every 7 days while the app runsYour licence key, your stored activation tokenWhether your licence is still active, the server time
Update checkAutomatic, on the update scheduleNothing: a plain, unauthenticated request for the current release manifestThe manifest, cryptographically signed, checked against a key built into the app before anything is trusted
Plugin registry checkBrowsing or updating pluginsNothing by default; if activated, your activation token, sent only to the registry addressThe plugin catalog, signed the same way as the update manifest
Plugin / update downloadsInstalling a plugin or accepting an updateNothing beyond the download request itselfThe plugin or installer file
Currency ratesYou type a currency conversion, such as 12 usd to inr; at most once an hour. A network feature: on by default, off with the Network features switch (below)Nothing about you; a plain request for the day’s exchange rates against USD, identical for every userThe day’s exchange rates

What’s deliberately not on this list: your searches, the files you open, what you type into the launcher, and your clipboard history. None of it is sent anywhere, ever, by any of the calls above.

Your IP address: like any web request, each of the six calls above reveals your IP address at the network level (to Cloudflare for the first five, to ExchangeRate-API for currency rates). That’s how the internet works, not something Nudge adds. No application logic in Nudge attaches your IP to your licence record or your identity beyond routine, short-lived request logs used for abuse prevention.

Network features, and how to turn them off

A network feature is an answer in the launcher that needs the internet to work. Today there is one: currency conversion. It’s on by default, and its result row says the rates come from the internet, so you can see when it’s being used. Settings → Privacy → Network features turns every network feature off at once; with it off, Nudge doesn’t make the currency-rates call at all, and a currency conversion says it’s turned off instead of fetching rates. Any network feature added in a future version follows the same switch and is added to the table above before it ships.

The switch covers answers in the launcher. It doesn’t cover activation, the licence heartbeat, the update check, or plugin downloads, which are listed separately above.

Bug reports: different from all of the above

Reporting a bug (Settings → About → Report a bug) does not automatically send anything. It builds a report on your machine (app version, OS version, which plugins you have installed, name/version only, and a stack trace made only of code frames) and shows it to you in full before doing anything. The report is never allowed to contain your search queries or file paths. The report format itself has no field for them, not just a setting that could be turned on. Sending it means it’s copied for you to paste into a GitHub issue yourself; the app does not silently upload it.

What stays on your PC

Nudge never saves your keystrokes as you type. When you run a result, Nudge remembers that result on your PC so it can rank it higher next time and show it in Recents: the result’s title and subtitle, its icon, what it does (for example the file or app it opens, the text it copies, or the command it runs), how many times you’ve run it, and when you last did. For a calculation, that includes the expression you typed; for a web search you ran, the search term; for a > command, the command itself.

All of this lives under %AppData%\Nudge (and a cache of app icons under %LocalAppData%\Nudge) on your PC. None of it is sent anywhere, by any of the calls above. Settings → Privacy lets you turn history off and clear it; you can also delete everything at any time by removing those folders, and uninstalling Nudge offers to remove them for you. Screen recordings you make are saved to your Pictures folder, and are never uploaded either.

The machine fingerprint

Activation and the licence heartbeat identify your machine by a hash, not by your machine’s real hardware IDs. The hash is built from a few Windows identifiers plus a random value generated once when Nudge is installed, and only that hash ever leaves your machine. Think of it as a pseudonymous install ID: it lets us tell “the same install checking in again” from “a different install,” without transmitting anything that identifies your actual hardware to us or to anyone else.

Who processes this data (our processors)

None of them receives your searches, files, or clipboard contents, because the app never transmits them.

How long we keep it

Licence and activation records are kept for as long as your licence is active, plus a limited period afterward for fraud prevention and support (for example, so a refund or a support request about a past purchase can still be resolved). If you ask us to delete your data, we deactivate your licence and remove what identifies you beyond what we’re required to keep for accounting or legal reasons.

How we protect it

The activation/heartbeat/update/registry endpoints are designed to run over standard encrypted web connections (HTTPS). That’s the intent behind how they’re built, not yet something a live, deployed, independently-tested backend has confirmed, since Phase 9.6’s backend hasn’t been deployed as of this writing. Your licence key and machine fingerprint are never stored in plain text alongside your email in a way that lets one be read from the other without the licence system itself. We don’t ask for or store a password: there’s no account, so there’s nothing to phish or credential-stuff.

If you’re in India (the Digital Personal Data Protection Act, 2023)

We act as a Data Fiduciary under India’s DPDP Act, 2023 for the personal data described in this policy (your email, licence key, and the pseudonymous install ID). In plain terms:

If you’re in the EU, UK, or somewhere with similar rules

Our basis for processing your data is performing the contract you bought (the licence) and our legitimate interest in preventing fraud and keeping the service running. You have the usual rights that come with that: to ask what we hold, to correct it, to have it deleted, and to complain to your local data protection authority if you think we’ve got something wrong. Start with the email below; most requests are simpler to just resolve directly.

What we don’t do

Your choices

Email hello@nudgelauncher.com to ask what’s on file for your licence, or to have it deleted (this deactivates the licence).

Changes to this policy

If the network calls this policy describes change in a future version, this page is updated before that version ships, and the “last updated” date changes with it.

Back to Nudge